Threats

BlackCat Ransomware Attacks Land Ex-Negotiator 4-Year Sentence

July 13, 2026 04:20 · 10 min read
BlackCat Ransomware Attacks Land Ex-Negotiator 4-Year Sentence

A former employee of cybersecurity incident response company DigitalMint has been sentenced to 70 months in prison for targeting U.S. companies in BlackCat (ALPHV) ransomware attacks.

Background of the Attacks

The FBI linked the BlackCat ransomware gang to more than 60 breaches between November 2021 and March 2022, adding that the cybercrime group had collected at least $300 million in ransom payments from more than 1,000 victims through September 2023.

41-year-old Angelo Martino was charged and pleaded guilty to his role in some of these attacks, along with two other Sygnia and DigitalMint ransomware negotiators, 28-year-old Kevin Tyler Martin and 33-year-old Ryan Clifford Goldberg.

Guilty Pleas and Sentences

Martin and Goldberg pleaded guilty in December to conspiracy to obstruct commerce by extortion and were also sentenced to four years in prison each in May.

Martino was initially identified only as 'Co-Conspirator 1' in an October 2025 indictment but was named in court documents unsealed in March.

Martino's Involvement in BlackCat Attacks

According to the court documents, between April 2023 and April 2025, Martino was directly involved in BlackCat ransomware attacks alongside accomplices Ryan Goldberg and Kevin Tyler Martin.

In one instance, 'In or around October 2023, ANGELO MARTINO, Ryan Clifford Goldberg, and Kevin Tyler Martin used ALPHV BlackCat ransomware to attack Victim 9,' reads the court documents.

'MARTINO, Goldberg, and Martin encrypted Victim 9's servers and demanded an approximate $1,000,000 ransom payment to decrypt the affected data and in exchange for a commitment not to publish the stolen information.'

Ransom Payments and Leaks

While operating as BlackCat affiliates, the three former Sygnia and DigitalMint employees demanded ransom payments and threatened to leak stolen data before encrypting their systems.

The three accomplices paid the BlackCat admins a 20% share of all ransom proceeds for access to the ransomware and extortion portal.

Sharing Confidential Information

Prosecutors added that Martino had also shared confidential information about victims' insurance policy limits and negotiation positions with BlackCat ransomware operators while working as a negotiator for five victims.

This allowed the cybercriminals to extort the maximum possible amount.

'Victim 1 hired Company 1, and MARTINO conducted the ransom negotiations on behalf of Company 1,' continued the complaint.

'During the ransom negotiations, MARTINO provided direction and confidential information to co-conspirators in order to maximize the ransom payment and in exchange for a portion of the ransom payment.'

Victim 1 paid the co-conspirators a ransom payment in virtual currency worth approximately $16,484,000 at the time of payment.

Victims of the Attacks

Their victims include at least five U.S. organizations, including a financial services firm that paid $25,660,000 and a nonprofit that paid a $26,793,000 ransom.

Other victims include school districts, medical facilities, law firms, and other financial services companies.

DigitalMint's Response

DigitalMint CEO Jonathan Solomon previously told BleepingComputer that the company condemned Martin and Martino's malicious conduct, noting that they were fired immediately after their actions were discovered.

'We strongly condemn these former employees' criminal behavior, which violated our values, ethical standards, and the law,' Solomon said.

'When we learned about the conduct, we immediately terminated both individuals,' Solomon added.

Security teams are advised to test every layer before attackers do, as the Picus whitepaper shows how breach and attack simulation tests SIEM and EDR rules to stop threats from slipping by detection.


Source: BleepingComputer

Source: BleepingComputer

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free